ATT&CKGroupsLazyScripter

LazyScripter

G0140

Threat group.View on attack.mitre.org

About this group

LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1027.010
Command Obfuscation

LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques.

T1036
Masquerading

LazyScripter has used several different security software icons to disguise executables.

T1059.001
PowerShell

LazyScripter has used PowerShell scripts to execute malicious code.

T1059.003
Windows Command Shell

LazyScripter has used batch files to deploy open-source and multi-stage RATs.

T1059.005
Visual Basic

LazyScripter has used VBScript to execute malicious code.

T1059.007
JavaScript

LazyScripter has used JavaScript in its attacks.

T1071.004
DNS

LazyScripter has leveraged dynamic DNS providers for C2 communications.

T1102
Web Service

LazyScripter has used GitHub to host its payloads to operate spam campaigns.

T1105
Ingress Tool Transfer

LazyScripter had downloaded additional tools to a compromised host.

T1204.001
Malicious Link

LazyScripter has relied upon users clicking on links to malicious files.

T1204.002
Malicious File

LazyScripter has lured users to open malicious email attachments.

T1218.005
Mshta

LazyScripter has used `mshta.exe` to execute Koadic stagers.

T1218.011
Rundll32

LazyScripter has used `rundll32.exe` to execute Koadic stagers.

T1547.001
Registry Run Keys / Startup Folder

LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key.

T1566.001
Spearphishing Attachment

LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector.

View all 20 procedure examples

Software7

Campaigns0

None recorded.

References1

  1. MalwareBytes LazyScripter Feb 2021 Open source
    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.